Home Malware Programs Adware EoRezo

EoRezo

Posted: November 7, 2011

Threat Metric

Ranking: 315
Threat Level: 2/10
Infected PCs: 3,771,999
First Seen: April 28, 2010
Last Seen: October 17, 2023
OS(es) Affected: Windows

EoRezo Screenshot 1EoRezo, also known as eoRezo, is a browser add-on that's distributed with GrabIt, an Usenet news server search utility. As adware, EoRezo may not be as damaging to your PC as a keylogger or virus. Although EoRezo may offer a removal utility for itself, it's suggested that you avoid taking EoRezo at its word and, instead, delete EoRezo with a responsible anti-malware program.
 

EoRezo: New Adware with Outdated Tricks to Show Off

EoRezo was first noted in October of 2011 and is often distributed with French versions of GrabIt installation packages. Although EoRezo may promote itself as a search enhancer or other kind of beneficial tool, EoRezo's features are entirely negative for your PC and include unpleasantly-invasive tactics like:

  • Taking control of your web browser away from you to redirect you to other websites. This includes creating advertisement pop-ups and changing your homepage or search engine settings.
  • Sending information about your PC out to third parties (most likely to allow them to target their advertisements to your online habits).
  • Connecting to external servers for instructions without your permission. Two known affiliates of EoRezo include alpha00001.com and, naturally, eorezo.com. It goes without saying, of course, that you should avoid these websites whenever it's possible to do so.

You may also experience worse Windows or web browser performance, since many of EoRezo's actions will occur in the background and eat up memory without giving you an option to disable them.
 

The Antidote to EoRezo's Browser Additions

SpywareRemove.com malware analysts stress the necessity of keeping your anti-malware programs up-to-date if you want them to be able to identify and remove EoRezo. Although some of EoRezo's symptoms may manifest in a particular web browser, deleting your browser will not delete EoRezo, which will remain in the background and continue to suck up your system resources.
 
If you're dealing with an EoRezo infection, you should try to minimize any contact that you have with EoRezo affiliates, including advertisements and the sites that these advertisements offer links towards. These sites can include scamware-selling websites or sites that use phishing techniques to steal private information. However, if you immediately scan your PC with a suitable anti-malware program to find and get rid of EoRezo, all EoRezo-related symptoms, including the presence of advertisement-based pop-ups, should cease.

Aliases

Adware/BHO [Panda]Adware/EoRezo.A.72 [AntiVir]Application.Generic.384998 [BitDefender]Win32:Eorezo-B [PUP] [Avast]Generic5.GFU [AVG]Win32.Malware [Ikarus]Adware:Win32/EoRezo [Microsoft]Adware/EoRezo.N.2 [AntiVir]Artemis!45CF2095378A [McAfee]TR/Agent.974848.7 [AntiVir]Artemis!06D4FED19763 [McAfee]Generic4.BZWZ [AVG]Eorezo [Sophos]Adware/EoRezo.E.9 [AntiVir]UnclassifiedMalware [Comodo]
More aliases (65)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\microsoft office\9w7qhrk4npxmyhrw8c4lkl\da2-y93atm.exe File name: da2-y93atm.exe
Size: 69.12 KB (69120 bytes)
MD5: 68518535700af96f78aab5ba356eb6be
Detection count: 2,164
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\microsoft office\9w7qhrk4npxmyhrw8c4lkl\da2-y93atm.exe
Group: Malware file
Last Updated: November 11, 2022
%PROGRAMFILES%\Windows Photo Viewer\U13C4NSLJU420TD24Q9HM2PLL9D\c9-08bX_Uq.exe File name: c9-08bX_Uq.exe
Size: 1.57 MB (1578496 bytes)
MD5: acb795c9a587100bbe9daf9b3de86fbe
Detection count: 1,637
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Windows Photo Viewer\U13C4NSLJU420TD24Q9HM2PLL9D\c9-08bX_Uq.exe
Group: Malware file
Last Updated: April 17, 2023
%PROGRAMFILES%\Windows Multimedia Platform\8UI0ZVZGYU6T64FBVZOJJ1CS6T3\404wfJSXFb.exe File name: 404wfJSXFb.exe
Size: 111.61 KB (111616 bytes)
MD5: dd0d67502265c9b55183dd0257489b19
Detection count: 1,450
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Windows Multimedia Platform\8UI0ZVZGYU6T64FBVZOJJ1CS6T3\404wfJSXFb.exe
Group: Malware file
Last Updated: April 10, 2022
%COMMONPROGRAMFILES%\N5M7KN\Yq5gPZjCvX.exe File name: Yq5gPZjCvX.exe
Size: 146.94 KB (146944 bytes)
MD5: 98b9644afd4de7674189556ca819b8e1
Detection count: 836
File type: Executable File
Mime Type: unknown/exe
Path: %COMMONPROGRAMFILES%\N5M7KN\Yq5gPZjCvX.exe
Group: Malware file
Last Updated: August 31, 2020
C:\Program Files\Windows Sidebar\LN5DPKV45LBVOHR9ELVL0AJBB\DTHLjesd0y.exe File name: DTHLjesd0y.exe
Size: 238.59 KB (238592 bytes)
MD5: b88955cbf36ca817df7ab5d64415b056
Detection count: 806
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Windows Sidebar\LN5DPKV45LBVOHR9ELVL0AJBB\DTHLjesd0y.exe
Group: Malware file
Last Updated: October 14, 2022
F:\Program Files (x86)\Formation\4571303.exe File name: 4571303.exe
Size: 5.39 MB (5392896 bytes)
MD5: 44032440596aa42cbb4bae2ff902b25b
Detection count: 803
File type: Executable File
Mime Type: unknown/exe
Path: F:\Program Files (x86)\Formation\4571303.exe
Group: Malware file
Last Updated: October 27, 2021
C:\Program Files\Windows Mail\ELAAXEQM6ASPSF6VXU5AJS02MI7\2Vi3oO42mK.exe File name: 2Vi3oO42mK.exe
Size: 604.16 KB (604160 bytes)
MD5: 6ced69cedb214f99015dc43a008e399f
Detection count: 637
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Windows Mail\ELAAXEQM6ASPSF6VXU5AJS02MI7\2Vi3oO42mK.exe
Group: Malware file
Last Updated: May 28, 2023
C:\WINDOWS\Windows Mail\RNIH88BR4KUITO1LAZR9RNJ5\trz6CF8.tmp File name: trz6CF8.tmp
Size: 545.79 KB (545792 bytes)
MD5: c47c904c27b70bce5f4ca0a4d97ff659
Detection count: 623
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\WINDOWS\Windows Mail\RNIH88BR4KUITO1LAZR9RNJ5\trz6CF8.tmp
Group: Malware file
Last Updated: December 27, 2021
%PROGRAMFILES%\k-lite codec pack x64\19xcr4a7jp7\&p#oqrzfgf.exe File name: &p#oqrzfgf.exe
Size: 216.06 KB (216064 bytes)
MD5: 205d9b12e59328c8e57ac92aa16ee3f8
Detection count: 438
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\k-lite codec pack x64\19xcr4a7jp7
Group: Malware file
Last Updated: April 12, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\LYFPI9RRVS\LYFP.exe File name: LYFP.exe
Size: 541.69 KB (541696 bytes)
MD5: b70ba5c079f815e03a95e004723404ad
Detection count: 403
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\LYFPI9RRVS\LYFP.exe
Group: Malware file
Last Updated: September 27, 2021
C:\Program Files\Realtek\E50ZZDE5S5C8MUEDRU7Q67RX\qV65-8lNN-.exe File name: qV65-8lNN-.exe
Size: 238.59 KB (238592 bytes)
MD5: ba4fc752a7d74b9a67b7f6a1a8075660
Detection count: 361
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Realtek\E50ZZDE5S5C8MUEDRU7Q67RX\qV65-8lNN-.exe
Group: Malware file
Last Updated: February 11, 2021
%PROGRAMFILES%\windowspowershell\d4pebmnuz6zfpmsn4a6gldtk52fw5xo0e\2brkriuga_.exe File name: 2brkriuga_.exe
Size: 206.33 KB (206336 bytes)
MD5: e280f49856c7cb7dd7de659742957ecd
Detection count: 323
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\windowspowershell\d4pebmnuz6zfpmsn4a6gldtk52fw5xo0e
Group: Malware file
Last Updated: April 15, 2020
%PROGRAMFILES%\tap-windows\rs3tlurqbqf5rmztr2v\owajxdaa'o.exe File name: owajxdaa'o.exe
Size: 290.3 KB (290304 bytes)
MD5: 5003ed514dae595cf15c0b68af607b62
Detection count: 201
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\tap-windows\rs3tlurqbqf5rmztr2v
Group: Malware file
Last Updated: March 1, 2022
%PROGRAMFILES%\Windows Mail\VPER3IM7BVRF13QK03TBX7A1PCUXT9VHIICMBZJ\z79hbçt-s#.exe File name: z79hbçt-s#.exe
Size: 536.06 KB (536064 bytes)
MD5: 190f8a1dc601f30ad7e3768fbcf8ea6e
Detection count: 33
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Windows Mail\VPER3IM7BVRF13QK03TBX7A1PCUXT9VHIICMBZJ\z79hbçt-s#.exe
Group: Malware file
Last Updated: June 26, 2020
%PROGRAMFILES%\optic\714338509.exe File name: 714338509.exe
Size: 486.4 KB (486400 bytes)
MD5: f56bcfa60e398b14e1b746e68b9329e6
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\optic\714338509.exe
Group: Malware file
Last Updated: June 27, 2020
%PROGRAMFILES(x86)%\charkoucha\710282148.exe File name: 710282148.exe
Size: 571.39 KB (571392 bytes)
MD5: f47425b1b9b9e6b8da09110c404858ae
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\charkoucha
Group: Malware file
Last Updated: August 23, 2019
%PROGRAMFILES(x86)%\zbidi\550802537.exe File name: 550802537.exe
Size: 515.07 KB (515072 bytes)
MD5: 5589be52bae041ddad72cc24e0845d08
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\zbidi
Group: Malware file
Last Updated: October 9, 2019
%PROGRAMFILES%\omek\516459642.exe File name: 516459642.exe
Size: 703.48 KB (703488 bytes)
MD5: dd6c5e4a7cad80c8b4949f4d13952359
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\omek
Group: Malware file
Last Updated: August 23, 2019
%PROGRAMFILES(x86)%\docroto\247435605.exe File name: 247435605.exe
Size: 799.23 KB (799232 bytes)
MD5: 1179589e86eb3a7e03b6c89e2586ebfb
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\docroto
Group: Malware file
Last Updated: August 23, 2019
%PROGRAMFILES(x86)%\avkzd\582164585.exe File name: 582164585.exe
Size: 714.75 KB (714752 bytes)
MD5: b53bdabd915570eeb2f60a86761240f9
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\avkzd
Group: Malware file
Last Updated: August 23, 2019

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{18AF7201-4F14-4BCF-93FE-45617CF259FF}{8FF10FED-2F0A-4F7F-BE87-B04F1DCD4319}{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}{DF76E9B7-35EC-46FC-AF56-5B79DED9D64F}File name without pathlightcleaner.lnklightcleanerlightcleaner.exelightcleanerlightcleaner.tmpLightening Media Player.lnkLighteningMediaPlayerInstall.exeSpeedycar.lnkRegexp file mask%PROGRAMFILES%\filters\xec.exe%PROGRAMFILES%\host\idscservice.exe%PROGRAMFILES%\host\w_network.exe%PROGRAMFILES%\host\wizzcaster.exe%PROGRAMFILES(x86)%\app\Wizard.exe%PROGRAMFILES(x86)%\filters\xec.exe%PROGRAMFILES(x86)%\host\idscservice.exe%PROGRAMFILES(x86)%\host\wizzcaster.exe%PROGRAMFILES(x86)%\pf\oo.exe%PROGRAMFILES(x86)%\Pipe\[NUMBERS].exe%TEMP%\avboost[RANDOM CHARACTERS].exe%TEMP%\speedycar[RANDOM CHARACTERS].exe%TEMP%\texttotalk.exe%USERPROFILE%\Desktop\texttotalk.lnk%WINDIR%\System32\Tasks\GoogleUpdateSecurityTaskMachine_[RANDOM CHARACTERS]HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\cibleSOFTWARE\Classes\tsckmnaSoftware\EoRezoSoftware\LightcleanerSOFTWARE\LighteningPlayerSoftware\MAL\SpeedycarSOFTWARE\Microsoft\2upsSOFTWARE\Microsoft\APreSamSOFTWARE\Microsoft\avboostcampaign114SOFTWARE\Microsoft\bestavicampaign563Software\Microsoft\BigTimeSOFTWARE\MICROSOFT\campaign9961SOFTWARE\Microsoft\DMunversionSOFTWARE\Microsoft\DskFXSoftware\Microsoft\EtsySOFTWARE\Microsoft\FstCarSOFTWARE\Microsoft\MPrForShutTSoftware\Microsoft\MPrForWeathISoftware\Microsoft\MTPreC_BSoftware\Microsoft\MTPreC_QnSOFTWARE\MICROSOFT\multitimercampaign84170SOFTWARE\Microsoft\PrAmNPSOFTWARE\Microsoft\PShutdTimeSOFTWARE\Microsoft\shutdowntimecampaign5651Software\Microsoft\ShutTPreAmSoftware\Microsoft\ShutTPreIcSoftware\Microsoft\ShutTPreJSoftware\Microsoft\ShutTPreShMSOFTWARE\MICROSOFT\SpeedycarSoftware\MICROSOFT\TechnologyDesktopnewSOFTWARE\Microsoft\Tracing\AfficheOne_RASAPI32SOFTWARE\Microsoft\Tracing\AfficheOne_RASMANCSSOFTWARE\Microsoft\Tracing\i_network_RASAPI32SOFTWARE\Microsoft\Tracing\i_network_RASMANCSSOFTWARE\Microsoft\Tracing\LighteningMediaPlayerInstall_RASAPI32SOFTWARE\Microsoft\Tracing\LighteningMediaPlayerInstall_RASMANCSSOFTWARE\Microsoft\Tracing\o_network_RASAPI32SOFTWARE\Microsoft\Tracing\o_network_RASMANCSSOFTWARE\Microsoft\Tracing\wizzcaster_RASAPI32SOFTWARE\Microsoft\Tracing\wizzcaster_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpeedycarSOFTWARE\Microsoft\Windows\CurrentVersion\Run\WeatherInspectSOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}SOFTWARE\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}Software\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}}Software\Picture\PictureprocessingToolsV1.0Software\Picture\seescenicelfcSoftware\Picture\seescenicelfqSoftware\Picture\seescenicelfuSOFTWARE\T4pcSoftware\UniversalCadastSOFTWARE\Wow6432Node\EoRezoSOFTWARE\Wow6432Node\Microsoft\DMunversionSOFTWARE\Wow6432Node\Microsoft\PrAmNPSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\SpeedycarSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\WeatherInspectSOFTWARE\Wow6432Node\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}SOFTWARE\Wow6432Node\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}Software\Wow6432Node\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}}SOFTWARE\Wow6432Node\Microsoft\{cc6eb6d8-85b7-435p-8b86-51e4d16ea76d}SYSTEM\ControlSet001\Services\AppApcVerifierSYSTEM\ControlSet002\Services\AppApcVerifierSYSTEM\CurrentControlSet\Services\AppApcVerifierHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}bestDownloader_is1comoBoss_is1eoEngine_is1eoRezo_is1LighteningPlayermaintenance software_is1Speedycar_is1texttotalkWeatherInspect_is1

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\AppApcVerifier%ALLUSERSPROFILE%\Application Data\AppApcVerifier%APPDATA%\EoRezo%APPDATA%\lighteningplayer%LOCALAPPDATA%\combroadcaster%PROGRAMFILES%\Ajc%PROGRAMFILES%\BeCleaner%PROGRAMFILES%\Caster%PROGRAMFILES%\ComoBo%PROGRAMFILES%\EoRezo%PROGRAMFILES%\KokoMoss%PROGRAMFILES%\Koruko%PROGRAMFILES%\LighteningPlayer%PROGRAMFILES%\Speedycar%PROGRAMFILES%\WeatherInspect%PROGRAMFILES%\WinCaster%PROGRAMFILES%\YEha%PROGRAMFILES%\bestDownloader%PROGRAMFILES%\browseextension%PROGRAMFILES%\comoBoss%PROGRAMFILES%\documentss%PROGRAMFILES%\elansurfer%PROGRAMFILES%\lightcleaner%PROGRAMFILES%\texttotalk%PROGRAMFILES%\tuto100_ar_21%PROGRAMFILES(X86)%\Caster%PROGRAMFILES(x86)%\Ajc%PROGRAMFILES(x86)%\BeCleaner%PROGRAMFILES(x86)%\ComoBo%PROGRAMFILES(x86)%\EoRezo%PROGRAMFILES(x86)%\KokoMoss%PROGRAMFILES(x86)%\Koruko%PROGRAMFILES(x86)%\LighteningPlayer%PROGRAMFILES(x86)%\Parklands%PROGRAMFILES(x86)%\Speedycar%PROGRAMFILES(x86)%\WeatherInspect%PROGRAMFILES(x86)%\WinCaster%PROGRAMFILES(x86)%\YEha%PROGRAMFILES(x86)%\bestDownloader%PROGRAMFILES(x86)%\browseextension%PROGRAMFILES(x86)%\comoBoss%PROGRAMFILES(x86)%\documentss%PROGRAMFILES(x86)%\elansurfer%PROGRAMFILES(x86)%\lightcleaner%PROGRAMFILES(x86)%\texttotalk%PROGRAMFILES(x86)%\tuto100_ar_21%TEMP%\bestDownloader%UserProfile%\Local Settings\Application Data\combroadcaster
Loading...